All of lore.kernel.org
 help / color / mirror / Atom feed
From: 市川正美 <masami.ichikawa@miraclelinux.com>
To: cip-dev <cip-dev@lists.cip-project.org>
Subject: Re: [cip-dev] New CVE entries this week
Date: Thu, 29 Jul 2021 17:11:14 +0900	[thread overview]
Message-ID: <CAODzB9q_2RC84Jt1joU8-FG7kaECsZtMn2uq7Zn8mXF6eC38tg@mail.gmail.com> (raw)
In-Reply-To: <20210729074703.GA14232@amd>

[-- Attachment #1: Type: text/plain, Size: 1904 bytes --]

Hi !

On Thu, Jul 29, 2021 at 4:47 PM Pavel Machek <pavel@denx.de> wrote:
>
> Hi!
>
> > ** Traking CVEs
> >
> > CVE-2021-21781: v4.4 is not fixed as of 2021/07/29
>
> This is basically missing memset. Does not look evil to backport.
>

Thanks.

> > CVE-2021-3655: v4.4 is not fixed as of 2021/07/29
>
> This may need more careful look. There are 4 patches fixing this in
> mainline, but only two in
> 5.10. c7da1d1ed43a6c2bece0d287e2415adf2868697e should be easy to
> backport to 4.4.
>

Okay. I'll take another look.

> > CVE-2021-31829: Linux kernel protection of stack pointer against
> > speculative pointer arithmetic can be bypassed to leak content of
> > kernel memory
> >
> > Fixed status
> > mainline: [f8be156be163a052a067306417cd0ff679068c97]
> > stable/4.19: [117777467bc015f0dc5fc079eeba0fa80c965149]
>
> Strange, this talks about CVE-2021-22543 in the changelog.
>

ok, I'll check again.

> > CVE-2021-31615: Unencrypted Bluetooth Low Energy baseband links in
> > Bluetooth Core Specifications 4.0 through 5.2
> >
> > Not fiexd in mainline yet
>
> > CVE-2021-3655: missing size validations on inbound SCTP packets
> >
> > According to cip-kernel-sec's scripts v4.4 is not fixed as of 2021/07/29
> >
> > One of a patch 50619dbf8db77e98d821d615af4f634d08e22698 is included.
> > https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/net/sctp?h=linux-4.4.y&id=48cd035cad5b5fad0648aa8294c4223bedb166dd
>
> I guess this should be listed in stable/4.4: ... then?
>

Yes, it is. I'll add it.

> Best regards,
>                                                                 Pavel
> --
> DENX Software Engineering GmbH,      Managing Director: Wolfgang Denk
> HRB 165235 Munich, Office: Kirchenstr.5, D-82194 Groebenzell, Germany
>
> 
>

Regards,

-- 
Masami Ichikawa
Cybertrust Japan Co., Ltd.

Email :masami.ichikawa@cybertrust.co.jp
          :masami.ichikawa@miraclelinux.com

[-- Attachment #2: Type: text/plain, Size: 429 bytes --]


-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#6641): https://lists.cip-project.org/g/cip-dev/message/6641
Mute This Topic: https://lists.cip-project.org/mt/84519830/4520388
Group Owner: cip-dev+owner@lists.cip-project.org
Unsubscribe: https://lists.cip-project.org/g/cip-dev/leave/10495289/4520388/727948398/xyzzy [cip-dev@archiver.kernel.org]
-=-=-=-=-=-=-=-=-=-=-=-


  reply	other threads:[~2021-07-29  8:11 UTC|newest]

Thread overview: 43+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2021-07-29  1:18 [cip-dev] New CVE entries this week 市川正美
2021-07-29  7:47 ` Pavel Machek
2021-07-29  8:11   ` 市川正美 [this message]
2021-07-29  8:58     ` Pavel Machek
2021-07-29  7:50 ` Nobuhiro Iwamatsu
2021-07-29  8:12   ` 市川正美
  -- strict thread matches above, loose matches on Subject: below --
2023-07-26 23:15 Masami Ichikawa
2023-07-27  9:26 ` [cip-dev] " Pavel Machek
2023-07-27 11:30   ` Masami Ichikawa
2023-06-14 22:43 Masami Ichikawa
2023-06-15  8:41 ` [cip-dev] " Pavel Machek
2023-06-15 11:52   ` Masami Ichikawa
2022-11-09 23:02 Masami Ichikawa
2022-11-10  8:33 ` [cip-dev] " Pavel Machek
2022-10-20  0:48 Masami Ichikawa
2022-10-20  7:58 ` [cip-dev] " Pavel Machek
2022-10-20 13:10   ` Masami Ichikawa
2022-06-15 23:44 Masami Ichikawa
2022-06-16 12:04 ` [cip-dev] " Pavel Machek
2022-06-08 23:44 Masami Ichikawa
2022-06-09  9:41 ` [cip-dev] " Pavel Machek
2022-06-09 12:06   ` Masami Ichikawa
2022-02-17  0:09 Masami Ichikawa
2022-02-17 11:55 ` [cip-dev] " Pavel Machek
2021-08-26  1:09 Masami Ichikawa
2021-08-26 10:01 ` Pavel Machek
     [not found] ` <169ED2F66B4753DB.9667@lists.cip-project.org>
2021-08-26 11:51   ` Pavel Machek
2021-08-26 12:43     ` Masami Ichikawa
2021-08-19  0:12 市川正美
2021-08-19  7:10 ` Pavel Machek
2021-08-19  8:37   ` Masami Ichikawa
2021-08-19  8:55   ` Nobuhiro Iwamatsu
2021-08-12  0:33 市川正美
2021-08-12  5:43 ` Pavel Machek
2021-08-12  8:40   ` 市川正美
2021-08-05  0:47 市川正美
2021-08-05  9:00 ` Pavel Machek
2021-08-06  0:46   ` 市川正美
2021-07-22  2:02 市川正美
2021-07-15  1:00 市川正美
2021-07-08  0:21 市川正美
2021-07-11  8:32 ` Pavel Machek
2021-07-11 11:13   ` masashi.kudo
2021-06-18  8:03 Pavel Machek
2021-06-20 23:51 ` 市川正美
2021-06-10 17:05 Pavel Machek
2021-06-17  2:09 ` 市川正美
2021-06-17 11:04   ` Masami Ichikawa
2021-06-18  8:01   ` Pavel Machek
2021-06-17  2:45 ` 市川正美

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=CAODzB9q_2RC84Jt1joU8-FG7kaECsZtMn2uq7Zn8mXF6eC38tg@mail.gmail.com \
    --to=masami.ichikawa@miraclelinux.com \
    --cc=cip-dev@lists.cip-project.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.